On Sept. 15, about $7.7M in rsETH was pulled from an Ethereum Safe. No owner key was stolen, and the Safe contracts weren’t the problem.
The wallet had a custom module that was already allowed to act for it. A missing access check let an outside caller use that permission without getting a new signature from the owners.
An MEV bot then spotted the transaction and got to the rsETH first. Kelp temporarily restricted the receiving address.
That changes how you look at a multisig. The signer threshold matters, but so does every module that can act without going back to those signers.
The wallet had a custom module that was already allowed to act for it. A missing access check let an outside caller use that permission without getting a new signature from the owners.
An MEV bot then spotted the transaction and got to the rsETH first. Kelp temporarily restricted the receiving address.
That changes how you look at a multisig. The signer threshold matters, but so does every module that can act without going back to those signers.
